Description
A flaw was found in cockpit-files. A local unprivileged attacker can exploit a race condition during directory creation with owner assignment. By controlling a writable parent directory, the attacker can replace a newly created directory with a symbolic link (symlink) before the ownership change operation (chown) is applied. This allows the attacker to redirect the ownership change to an arbitrary file, potentially leading to information disclosure or unauthorized modification of sensitive files.
Published: 2026-09-18
Score: 6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Hijacked file ownership leading to unauthorized modification or disclosure
Action: Patch Now
AI Analysis

Impact

A race condition in cockpit-files allows a local unprivileged attacker that can write to a chosen directory to replace a freshly created directory with a symbolic link before the ownership change function (chown) is executed. This maneuver redirects the ownership change to the target of the symlink, giving the attacker control over the ownership of an arbitrary file. The attacker can thus gain unintended file ownership, potentially reading protected data or modifying critical system files, which compromises confidentiality and integrity of the system.

Affected Systems

The flaw affects Red Hat Enterprise Linux 10 and 9, specifically the cockpit-files component. No specific version numbers are listed, so any installation of cockpit-files on these operating systems should be considered vulnerable until an update is applied.

Risk and Exploitability

The vulnerability has a CVSS score of 6, indicating moderate severity. EPSS is not available, so the estimated probability of exploitation is unknown, though the attack requires local execution and the ability to create files in a directory that cockpit-files can later chown. The vulnerability is not listed in the CISA KEV catalog. An attacker who successfully exploits the race might redirect ownership to an arbitrary file, potentially leading to information disclosure or unauthorized file modification.

Generated by OpenCVE AI on September 19, 2026 at 10:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Red Hat security update for cockpit-files that eliminates the symlink race condition.
  • If an update is unavailable, change the ownership and permissions of directories used by cockpit-files to remove write access from unprivileged users.
  • Enable filesystem integrity monitoring to detect unexpected symlink creation or ownership changes in critical directories.

Generated by OpenCVE AI on September 19, 2026 at 10:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description A flaw was found in cockpit-files. A local unprivileged attacker can exploit a race condition during directory creation with owner assignment. By controlling a writable parent directory, the attacker can replace a newly created directory with a symbolic link (symlink) before the ownership change operation (chown) is applied. This allows the attacker to redirect the ownership change to an arbitrary file, potentially leading to information disclosure or unauthorized modification of sensitive files.
Title Cockpit-files: cockpit-files: local attacker can hijack file ownership via symlink race
First Time appeared Redhat
Redhat enterprise Linux
Weaknesses CWE-363
CPEs cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
References
Metrics cvssV3_1

{'score': 6, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N'}


Subscriptions

Redhat Enterprise Linux
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-22T22:41:33.130Z

Reserved: 2026-09-14T21:59:16.679Z

Link: CVE-2026-91205

cve-icon Vulnrichment

Updated: 2026-09-21T20:05:42.712Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T20:17:29.533

Modified: 2026-09-22T19:37:36.747

Link: CVE-2026-91205

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-18T16:33:00Z

Links: CVE-2026-91205 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T19:24:54Z

Weaknesses
  • CWE-363

    Race Condition Enabling Link Following